Impact
The vulnerability resides in the Metadata Plugin component of Oracle Enterprise Manager Base Platform, enabling a low‑privileged attacker with network access via HTTPS to compromise the platform and gain full control. This flaw is identified as CWE-269. The CVSS 3.1 base score of 8.8 signals high confidentiality, integrity, and availability impact, and the vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates that remote exploitation does not require user interaction.
Affected Systems
Oracle Enterprise Manager Base Platform version 13.5 and version 24.1 are affected. The vulnerability is present in the Metadata Plugin component of these deployments.
Risk and Exploitability
The CVSS score of 8.8 flags the vulnerability as high severity, while the EPSS score of <1% implies a low to very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, meaning no publicly available exploit is known as of this analysis. Based on the description, the likely attack vector involves a low‑privileged attacker who can reach the HTTPS interface of an unpatched Enterprise Manager instance; successful exploitation would lead to takeover of the platform and unrestricted access to all managed assets.
OpenCVE Enrichment